Codex Discovered a Hidden HTTP/2 Bomb Домашний компьютер… — Cybred — TG.ME

Codex Discovered a Hidden HTTP/2 Bomb

Домашний компьютер, подключенный к сети со скоростью 100 Мбит/с, может сделать уязвимый сервер недоступным в считанные секунды. В случае с Apache httpd и Envoy один клиент "забивает" 32 ГБ памяти сервера примерно за 20 секунд.

Новая уязвимость, которая работает против NGINX, Apache HTTPD, Microsoft IIS, Envoy, и Cloudflare Pingora.

The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it.


Shodan: ssl.alpn:"h2" product:nginx,Apache,IIS,Envoy,Pingora

PoC: http2-bomb
blog.calif.io
Codex Discovered a Hidden HTTP/2 Bomb
14 years ago, I helped break HTTP header compression, then was asked to review the fix, which became part of HTTP/2. Life has come full circle: today we're releasing an attack I missed.
June 3, 2026 5.9K 156